CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-54090
5.9 MEDIUM

A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). …

Feb 11, 2025
CVE-2024-53977
6.7 MEDIUM

A vulnerability has been identified in ModelSim (All versions < V2025.1), Questa (All versions < V2025.1). An example setup script contained in affected applications allows …

Feb 11, 2025
CVE-2024-53651
4.6 MEDIUM

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions), SIPROTEC …

Feb 11, 2025
CVE-2024-53648
6.8 MEDIUM

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All …

Feb 11, 2025
CVE-2024-23814
5.3 MEDIUM

The integrated ICMP service of the network stack of affected devices can be forced to exhaust its available memory resources when receiving specially crafted messages …

Feb 11, 2025
CVE-2024-13506
6.4 MEDIUM

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the display_name profile parameter …

Feb 11, 2025
CVE-2023-37482
5.3 MEDIUM

The login functionality of the web server in affected devices does not normalize the response times of login attempts. An unauthenticated remote attacker could exploit …

Feb 11, 2025
CVE-2025-26409
6.8 MEDIUM

A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader …

Feb 11, 2025
CVE-2025-26408
6.1 MEDIUM

The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the …

Feb 11, 2025
CVE-2025-1182
5.0 MEDIUM

A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_reloc_symbol_deleted_p of the file bfd/elflink.c of the component …

Feb 11, 2025
CVE-2025-0589
5.3 MEDIUM

In affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible for an unauthenticated user to make an API …

Feb 11, 2025
CVE-2025-1181
5.0 MEDIUM

A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. …

Feb 11, 2025
CVE-2024-52612
6.8 MEDIUM

SolarWinds Platform is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. This vulnerability requires authentication by …

Feb 11, 2025
CVE-2024-45718
4.6 MEDIUM

Sensitive data could be exposed to non- privileged users in a configuration file. Local access to the computer with a low- privileged account is required …

Feb 11, 2025
CVE-2024-28989
5.5 MEDIUM

SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive information from the software.

Feb 11, 2025
CVE-2025-1179
5.0 MEDIUM

A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file …

Feb 11, 2025
CVE-2025-1178
5.6 MEDIUM

A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file …

Feb 11, 2025
CVE-2025-1177
6.3 MEDIUM

A vulnerability was found in dayrui XunRuiCMS 4.6.3. It has been classified as critical. Affected is the function import_add of the file dayrui/Fcms/Control/Admin/Linkage.php. The manipulation …

Feb 11, 2025
CVE-2025-1176
5.0 MEDIUM

A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component …

Feb 11, 2025
CVE-2024-13570
6.1 MEDIUM

The Stray Random Quotes WordPress plugin through 1.9.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Feb 11, 2025
CVE-2024-13544
4.8 MEDIUM

The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files …

Feb 11, 2025
CVE-2024-13543
6.1 MEDIUM

The Zarinpal Paid Download WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Feb 11, 2025
CVE-2025-1211
6.5 MEDIUM

Versions of the package hackney before 1.21.0 are vulnerable to Server-side Request Forgery (SSRF) due to improper parsing of URLs by URI built-in module and …

Feb 11, 2025
CVE-2025-1173
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in 1000 Projects Bookstore Management System 1.0. This affects an unknown part of the file process_users_del.php. …

Feb 11, 2025
CVE-2024-12599
6.4 MEDIUM

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions …

Feb 11, 2025
CVE-2025-1172
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0. Affected by this issue is some unknown functionality …

Feb 11, 2025
CVE-2025-1145
6.1 MEDIUM

NetVision Information ISOinsight has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript code in the user's browser through phishing techniques.

Feb 11, 2025
CVE-2025-1168
6.3 MEDIUM

A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been declared as critical. This vulnerability affects unknown code of …

Feb 11, 2025
CVE-2025-1167
6.3 MEDIUM

A vulnerability was found in Mayuri K Employee Management System up to 192.168.70.3 and classified as critical. Affected by this issue is some unknown functionality …

Feb 11, 2025
CVE-2025-1166
6.3 MEDIUM

A vulnerability has been found in SourceCodester Food Menu Manager 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Feb 11, 2025
CVE-2025-25241
5.4 MEDIUM

Due to a missing authorization check, an attacker who is logged in to application can view/ delete �My Overtime Requests� which could allow the attacker …

Feb 11, 2025
CVE-2025-24875
6.8 MEDIUM

SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying …

Feb 11, 2025
CVE-2025-24874
6.8 MEDIUM

SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protection remains effective now, it may not be the case in …

Feb 11, 2025
CVE-2025-24872
4.3 MEDIUM

The ABAP Build Framework in SAP ABAP Platform allows an authenticated attacker to gain unauthorized access to a specific transaction. By executing the add-on build …

Feb 11, 2025
CVE-2025-24870
6.0 MEDIUM

SAP GUI for Windows & RFC service credentials are incorrectly stored in the memory of the program allowing an unauthenticated attacker to access information within …

Feb 11, 2025
CVE-2025-24869
4.3 MEDIUM

SAP NetWeaver Application Server Java allows an attacker to access an endpoint that can disclose information about deployed server components, including their XML definitions. This …

Feb 11, 2025
CVE-2025-24867
6.1 MEDIUM

SAP BusinessObjects Platform (BI Launchpad) does not sufficiently handle user input, resulting in Cross-Site Scripting (XSS) vulnerability. The application allows an unauthenticated attacker to craft …

Feb 11, 2025
CVE-2025-23193
5.3 MEDIUM

SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a …

Feb 11, 2025
CVE-2025-23190
4.3 MEDIUM

Due to missing authorization check, an authenticated attacker could call a remote-enabled function module which allows them to access data that they would otherwise not …

Feb 11, 2025
CVE-2025-23189
4.3 MEDIUM

Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an authenticated attacker could generate technical meta-data. This leads to a …

Feb 11, 2025
CVE-2025-23187
5.3 MEDIUM

Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-data. This leads to a …

Feb 11, 2025
CVE-2025-0054
5.4 MEDIUM

SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user …

Feb 11, 2025
CVE-2025-1164
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in code-projects Police FIR Record Management System 1.0. This issue affects some unknown processing of …

Feb 11, 2025
CVE-2025-1163
5.3 MEDIUM

A vulnerability classified as critical was found in code-projects Vehicle Parking Management System 1.0. This vulnerability affects the function login of the component Authentication. The …

Feb 11, 2025
CVE-2025-25194
4.0 MEDIUM

Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation …

Feb 10, 2025
CVE-2025-1162
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. This affects an unknown part of the file /\_parse/load\_user-profile.php. The manipulation of …

Feb 10, 2025
CVE-2025-25193
5.5 MEDIUM

Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially …

Feb 10, 2025
CVE-2025-1158
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5.6.3.154.205_20250114. It has been classified as critical. Affected is an unknown function of the file addPolicyToSafetyGroup.jsp. The manipulation …

Feb 10, 2025
CVE-2025-1157
6.3 MEDIUM

A vulnerability was found in Allims lab.online up to 20250201 and classified as critical. This issue affects some unknown processing of the file /model/model_recuperar_senha.php. The …

Feb 10, 2025
CVE-2025-1002
5.7 MEDIUM

MicroDicom DICOM Viewer version 2024.03 fails to adequately verify the update server's certificate, which could make it possible for attackers in a privileged network position …

Feb 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.